Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple directory traversal vulnerabilities in AZ Bulletin board (AZbb) before 1.0.08 allow (1) remote authenticated users with administrative privileges to delete arbitrary files via a .. (dot dot) in the URL to admin_avatar.php or admin_attachment.php or (2) remote attackers to enumerate files via a .. (dot dot) in the attachment parameter to attachment.php, which displays a different message when a file exists or does not exist.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MAZ Bulletin board (AZbb) 1.0.08目录遍历漏洞
Vulnerability Description
MAZ Bulletin board (AZbb) 1.0.08版本中的多个目录遍历漏洞,允许(1)具有管理员权限的远程验证用户通过admin_avatar.php或admin_attachment.php的URL中的..(参数中包含'..')来删除任意文件,或允许(2)远程攻击者通过attachment.php的attachment参数中的..(参数中包含'..')来枚举文件,从而在文件存在或不存在的情况下显示相反的消息。
CVSS Information
N/A
Vulnerability Type
N/A